zc-bug-fix

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its bug-fix purpose, but it concentrates sensitive ZenTao and GitLab credentials in a local config and forwards them to unreviewed shell scripts that perform networked state changes. No obvious malicious exfiltration or deceptive installer is present, yet the credential handling, private/self-hosted endpoints, and ability to push code and update trackers make the overall risk medium.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:42 AM
Package URL
pkg:socket/skills-sh/ruiwarn%2Fskills%2Fzc-bug-fix%2F@b507ab8db43e120ea0c05a36c1210880dae67354